CVE-2026-32475 : un visiteur anonyme peut déposer et exécuter un fichier PHP via un formulaire Elementor Pro. Voici comment protéger votre site WordPress.
Le post Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress a été publié sur IT-Connect.
Bannières animées, visuels contextuels, publicités vidéo... La publicité display est aujourd'hui omniprésente sur le web et demeure l'un des leviers les plus puissants pour développer sa notoriété, générer du trafic et convertir. Pourtant, entre le choix des formats, la finesse du ciblage et l'optim...
The good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had.
The bad news? It gives attackers the same capability.
This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make...
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.
Ransomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI, forcing the need for a change in how organi...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf...
Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities.
The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler AD...
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has tar...
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant environment and reg...
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly acc...
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.
The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's clo...
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page c...
Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organization...
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ...
Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling...
Ubuntu's USN-8657-1 announced multiple Vim vulnerabilities affecting various LTS versions, allowing potential denial of service and arbitrary code execution. Updates are available to fix these issues.